Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,443Referência 21,797GitHub PoC 13,885VulnCheck XDB 8,484Nuclei 4,237Metasploit 3,467✓ verified onlyrecentpopularrisk
21,692 exploits
Referência✓ VexDay Proof
Joomla! Component Car Manager 1.1 - SQL Injection
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows re
23RISK
open ↗Referência✓ VexDay Proof
XOOPS Module myAlbum-P 2.0 - 'cid' SQL Injection
SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remo
23RISK
open ↗Referência✓ VexDay Proof
Battle.net Clan Script for PHP 1.5.1 - SQL Injection
SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows re
23RISK
open ↗Referência✓ VexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users t
23RISK
open ↗Referência✓ VexDay Proof
Elkagroup Image Gallery 1.0 - SQL Injection
SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
ArcadeBuilder Game Portal Manager 1.7 - SQL Injection
SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL co
23RISK
open ↗Referência✓ VexDay Proof
WebChat 0.78 - 'login.php?rid' SQL Injection
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open ↗Referência
CVE-2009-3215
SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allow
23RISK
open ↗Referência✓ VexDay Proof
PHP123 Top Sites - 'category.php?cat' SQL Injection
SQL injection vulnerability in category.php in PHP123 Top Sites allows remote attackers to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
SimpleBlog 3.0 - 'comments_get.asp?id' SQL Injection
SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open ↗Referência✓ VexDay Proof
ABC estore 3.0 - 'cat_id' Blind SQL Injection
SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open ↗Referência✓ VexDay Proof
Blog:CMS 4.2.1b - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (
23RISK
open ↗Referência✓ VexDay Proof
Joomla! Component com_doc - SQL Injection
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execu
23RISK
open ↗Referência✓ VexDay Proof
PHP-Nuke Module EasyContent - 'page_id' SQL Injection
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
vShare YouTube Clone 2.6 - 'tid' SQL Injection
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary
23RISK
open ↗Referência✓ VexDay Proof
easyTrade 2.x - 'id' SQL Injection
SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
FlashGet 1.9 - 'FTP PWD Response' Remote Buffer Overflow (PoC)
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RISK
open ↗Referência✓ VexDay Proof
FlashGet 1.9.0.1012 - 'FTP PWD Response' Remote Buffer Overflow (SafeSEH)
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RISK
open ↗Referência
CVE-2022-45707
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijac
48RISK
open ↗Referência
CVE-2022-45708
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDel
48RISK
open ↗Referência
CVE-2022-45710
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule p
48RISK
open ↗Referência
CVE-2022-45712
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForwa
48RISK
open ↗Referência
CVE-2022-45714
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formQOSRuleD
48RISK
open ↗Referência
CVE-2022-45715
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRang
48RISK
open ↗Referência
CVE-2022-45716
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBin
48RISK
open ↗Referência
CVE-2022-45718
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAd
48RISK
open ↗Referência
CVE-2022-45719
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAut
48RISK
open ↗Referência
CVE-2022-45720
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters
48RISK
open ↗Referência
CVE-2022-45706
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCh
48RISK
open ↗Referência
CVE-2014-9457
SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.